The CMMC will be a unified cybersecurity standard for DOD acquisitions which will boost the cybersecurity posture of the Defense Industrial Base (DIB). The certification focuses on various cybersecurity standards and best practices that range from basic cyber hygiene to the more advanced cybersecurity controls.
To gain a CMMC certification, a contractor will need to understand the associated practices that when implemented, will reduce risk against a specific set of cyber threats. The CMMC is intended to be cost-effective and affordable for small businesses to implement at the lower CMMC levels. Certified independent 3rd party organizations will conduct audits and inform risk, depending on the kinds of data a contractor is handling.
Most of the information that has been released on the CMMC is provisional and has been released by The Office of the Under Secretary of Defense for Acquisition and Sustainment. They are set to release a final version (Rev 1.0) in January 2020 with another version that includes Requests for Proposals in June 2020.
The levels of the CMMC have been outlined as: